Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Public Lands Are at the Forefront of Wyoming’s Primaries

    August 17, 2026

    Private Schools Where 100% of Students Use Vouchers Barely Face Any Oversight — ProPublica

    August 17, 2026

    Ebola is Back-and the IMF’s Relief Fund Is Empty by Marina Zucker-Marques

    August 17, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Public Lands Are at the Forefront of Wyoming’s Primaries
    • Private Schools Where 100% of Students Use Vouchers Barely Face Any Oversight — ProPublica
    • Ebola is Back-and the IMF’s Relief Fund Is Empty by Marina Zucker-Marques
    • French PM Lecornu booed by residents on visit to fire-ravaged southwest
    • Changing pubs into offices or homes to be made harder under new rules
    • Burnham exchanged messages with individual impersonating Trump chief of staff | Andy Burnham
    • Skylight Buddy Review (2026): Kid Routines Just Got Easy
    • DeepSeek AI Releases DeepSeek Harness in Developer Preview: An MIT-Licensed Agent Harness Where Everything is a Plugin
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, August 17
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Recent macOS Screen Sharing Vulnerability Exploited in Attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 17, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors are exploiting a recently patched macOS vulnerability to gain root access and deploy cryptominers.

    The exploited bug, tracked as CVE-2026-65400, is a high-severity authentication issue in Screen Sharing that allows remote attackers to log in without valid credentials.

    Apple disclosed the flaw on August 6, when it rolled out fixes in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9.

    Roughly a week later, the Dutch National Cyber Security Centrum (NCSC) warned that in-the-wild exploitation has started, fueled by the existence of a public proof-of-concept (PoC) exploit.

    “The NCSC has received a notification showing that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the internet,” NCSC says.

    Threat actors have been exploiting the security defect to gain root access to the vulnerable systems and install a Monero miner, it says.

    Advertisement. Scroll to continue reading.

    “Apple has improved state management mechanisms to enforce correct validation of login credentials and prevent unauthorized authentication attempts,” NCSC notes.

    According to AI security firm Calif, the flaw allows a remote attacker to authenticate to a macOS system that has Screen Sharing enabled by simply naming an account.

    “Naming an account is the one thing the bug needs. It is not much of a barrier. A username is not a secret, and macOS prints them on the login window,” Calif notes.

    CVE-2026-65400, however, is not the only recently patched vulnerability in screensharingd, the daemon responsible for managing Screen Sharing connections.

    In late July, Apple patched at least four other issues in it, including three that have CVE identifiers. Reportedly, the fourth, which was silently addressed, was the most severe of them, as it allowed unauthenticated attackers to gain remote code execution as root.

    According to security researcher osxreverser, the issue could be exploited to take over any macOS with Screen Sharing enabled, as long as the attacker knew its IP address and SIP was disabled.

    The flaw reportedly did not require user interaction and could allow an attacker to plant a reverse shell and a root crontab through the same connection.

    On August 8, osxreverser warned that approximately 40,000 internet-accessible macOS systems had Screen Sharing enabled, meaning that they were potentially exposed to attacks.

    Related: Hackers Exploiting Unpatched GeoServer Zero-Day

    Related: Adobe Commerce Bug Targeted Immediately After Disclosure

    Related: WordPress 7.0.4 Patches Remote Code Execution Vulnerability

    Related: Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

    attacks Exploited macOS Screen sharing Vulnerability
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    French tax authority data breach affects 678,000 individuals

    SafePal breach exposes 40,000 customers as hardware wallet attacks escalate from data leaks to $100 million theft

    Coinbase-Circle USDC revenue sharing, FOMC minutes, oil price: Crypto Week Ahead

    Offshore Wind Will Struggle Long After Trump’s Attacks

    New CISO appointments 2026 | CSO Online

    Scientists tracked kids for 8 years — the screen time result was unexpected

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Public Lands Are at the Forefront of Wyoming’s Primaries

    August 17, 2026

    Private Schools Where 100% of Students Use Vouchers Barely Face Any Oversight — ProPublica

    August 17, 2026

    Ebola is Back-and the IMF’s Relief Fund Is Empty by Marina Zucker-Marques

    August 17, 2026

    French PM Lecornu booed by residents on visit to fire-ravaged southwest

    August 17, 2026
    Latest Posts

    Heathrow expansion would take thousands of jobs from other UK regions, report finds | Heathrow third runway

    July 27, 2026

    Farage’s latest gamble clouds Reform’s path to power – POLITICO

    July 27, 2026

    Pauline Hanson loses bid to overturn Mehreen Faruqi racial discrimination finding | Australian Greens

    July 27, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Public Lands Are at the Forefront of Wyoming’s Primaries

    August 17, 2026

    Private Schools Where 100% of Students Use Vouchers Barely Face Any Oversight — ProPublica

    August 17, 2026

    Ebola is Back-and the IMF’s Relief Fund Is Empty by Marina Zucker-Marques

    August 17, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.